Legal

Privacy Policy

Last updated: July 21, 2026

This policy explains what data PowerMyWeb (operated by Yihang Huang) collects, why, and what control you have over it. The short version: your résumé is used to build your site and for nothing else of ours, we don’t sell your data, and you can ask us to delete what we hold by emailing us.

1. What we collect

  • Career materials you provide: résumé files (PDF/DOCX/text), a GitHub username or profile URL (we fetch only publicly available data), project images, and anything you type into the builder or the editing chat. Résumés often contain sensitive personal data — please remove anything you do not want processed (e.g. national ID numbers) before uploading.
  • Account data: when you sign in with Google or GitHub we receive your name, email address, and avatar. We never receive your password.
  • Usage and log data: standard server logs (IP address, request time, user-agent) used for security, rate limiting, and debugging.
  • Payment data: checkout is handled by our merchant of record. We receive your subscription status and limited billing metadata (such as plan and renewal dates) — never your full card details.

2. How we use it

  • To generate, edit, and host your portfolio website — the core of the Service.
  • To operate your account, enforce plan quotas, and provide support.
  • To protect the Service (abuse prevention, rate limiting, security).

We do not sell or rent your personal data, use it for advertising, or use your content to train AI models ourselves.

3. AI processing — where your résumé goes

Site generation is performed by large language models provided by Zhipu AI (Beijing, China). When you generate or edit a site, the relevant content (your résumé text, profile summary, and instructions) is transmitted to Zhipu AI’s API for processing. That processing is governed by Zhipu AI’s own API terms and privacy policy, which control their retention and use of submitted content — we can only speak for our own conduct. We send only what is needed for generation, and we are transparent about this so you can decide what to upload. If you are not comfortable with this processing, please do not use the Service.

4. Where data is stored

  • In your browser: drafts and working sessions are stored locally (IndexedDB) on your device. They stay there until you clear them (browser site-data settings) — we cannot delete your local copies for you.
  • In our cloud: when you create an account, your projects and published sites are stored on our infrastructure (Vercel and Neon, hosted in the United States).
  • Published sites: anything you publish to *.powermyweb.com is public — visible to anyone with the link, and search engines may index and cache it. Unpublishing removes the site from our servers but cannot remove copies already made by third parties or search caches. Don’t publish information you want to keep private.

5. Who receives data

  • Service providers processing on our behalf: Zhipu AI (AI generation, see section 3), Vercel (hosting and content delivery), Neon (database).
  • Independent services you interact with: our merchant of record (the checkout entity named at purchase) processes payments under its own privacy policy; Google or GitHub handle sign-in under theirs.
  • The public, at your direction: whatever you choose to publish (section 4).
  • We may disclose data if required by law.

6. Security and breach notification

We use reasonable technical and organizational measures appropriate to the nature of the data — encrypted connections (HTTPS/TLS), access controls and least-privilege credentials for our infrastructure, rate limiting, and input validation. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will investigate and notify you and the relevant authorities as required by applicable law.

7. Retention and deletion

We keep your data while your account is active. You can delete individual projects in the app, or email support@powermyweb.com to delete your account and the data in systems we control (our database and hosting storage) — we complete such requests within 30 days, except for residual copies in routine backups (purged on backup rotation) and records we must keep for legal, security, or fraud purposes. Content already processed by providers in section 5 is subject to their own retention policies, and section 4 explains the limits around local copies and public caches. Server logs are retained for at most 90 days.

8. Your rights

Regardless of plan, you can request: a copy of the personal data we hold about you (including your site content in a portable form), correction of inaccurate data, or deletion — via support@powermyweb.com. We may need to verify your identity (normally by matching your account email). We respond within the period required by applicable law, and normally acknowledge within 3 business days. If you are unsatisfied, you may complain to your local data-protection authority. The Pro plan’s one-click HTML export is a convenience feature and is separate from these statutory rights.

9. Cookies

We use only essential cookies: keeping you signed in and protecting against request forgery. No advertising or cross-site tracking cookies. Third-party checkout or sign-in pages may set their own cookies under their own policies.

10. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from them. If we learn that we have, we will delete it.

11. Changes

We will post any changes here and update the date above. For material changes we will give direct notice (email or in-product) before they take effect, and where a new use of your data requires consent, we will ask for it rather than assume it.

12. Contact

Privacy questions or requests: support@powermyweb.com. See also our Terms of Service.